. Application/Control Number: 09/765,431 
Art Unit: *** 



Page 2 



CLMPTO 
SDS 
02/03/03 
12/01/04 



Application/Control Number: 09/765,431 Page 3 

Art Unit: *** 

1. A method for monitoring performance on a network, the method comprising: 

(a) running at least one performance monitor process on the network; 

(b) running a network monitor manager process on the network; 

(c) establishing a socket connection from the network monitor manager process to said at 
least one performance monitor process to control said at least one performance monitor to 
<s&nd a pseudo message to an entry server; and 

<d) receiving the pseudo message from said at learn one performance monitor process and 
determming a respoase for the pseudo message for each segment of the network traversed by 
the pseudo message, 

2- The method of claim U further comprising: 

(e) running at least one availability monitor process on the network; 

(f) from the response determined in step (d% detecting at least one possibly failed 
component of the network; 

(g) sending a message from the at least one availability monitor process to the at least 
one possibly Jailed component; and 

(h) determining, in accordance with a result of the message, whether the at l east one 
possibly failed component has failed, 

3* The method of claim 1,. further comprising; 

(i) miming a ciieni-server monitoring process on a server dedicated to the client- 
server monitoring process; 

Q) recei ving, in the ciient-server monitoring process, information about transactions 

executed by production applications on the network; and 

(k) determining performance and availability of the production applications in 

accordance with the information received in step (j). 
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4. The method of claim 3, wherein step (j) comprises running a filtering agent on each of the 
production applications to convert the information into a form usable by the client-server 
monitoring process. 

5. The method of claim 4, wherein: 

the network comprises a mainframe having at least one logical partition which 
generates an application fog; and 

the method further comprises (1) monitoring the application log through a mainframe 
monitoring process, 

6. (Amended) The method of claim 5, wherein; 

the application log comprises transaction entries having end-user addresses; and 
step (I) comprises categorizing the transaction entries by the end-user addresses. 
7« The method of claim 6, further comprising (m) generating a performance report for the 
network through an administrative process and making the report available over a data 
network. 

8 + The method of claim 7, wherein the data network comprises the Internet. 
9. (Amended) The method of claim 8, itaxher comprising: 

(n) recei ving, in the client-server monitoring process, information about transactions 
executed by e-commerce applications on the network; and 

(o) determining performance and availability of the e-commerce applications in accordance 
with the information received in step (n) through an ^commerce monitoring process. 
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10. (Amended) The method of claim 9, wherein at least one of the e-commerce applications 
makes at least one Web page accessible to customers, and wherein step (n) comprises placing 
code in the at feast one Web page, the code sending time stamps to the client-server monitoring 

process when the code is accessed. _ 

1 1 . The method of claim 10, further comprising providing a central data repository, and 

wherein the network monitor manager process, the client-server monitoring process, die 
mainframe monitoring process, the administrative process, and the ^commerce monitoring 
process communicate with one another through the central data repository. 

12. The method of claim 4, wherein each said liltering agent detects processes running on the 
network and cross-references the detected processes- to known processes, and ftirther 
comprising forming m event correlation engine in accordance with the detected processes. 

13. The method of claim 12, wherein each said filtering agent detects changes to the 
processes miming on the network, and further comprising maintaining the event correlation 
engine in accordance with the detected changes to the processes. 

1 4. The method of claim 1 3 P further comprising, when it is determined in step (k) that the 
performance or the availability of one of the production applications is unpai'ted^dete^ining 
and reporting a cause of impairment and its corresponding effect on an SI A in accordance 
with the event correlation engine. 



